What does the auditor's first Information Document Request include?
The CA CDTFA Audit Manual, [1] NY DTF Publication 130-D, [2] and TX Comptroller Audit Procedures Manual [3] describe substantially the same opening request. Vocabulary varies across states. California issues an Audit Engagement Letter with an attached document list; New York leads with a Records Review Request; Texas issues an Audit Questionnaire followed by a formal records request. The underlying inventory is consistent across the three highest-volume audit states for multi-channel ecommerce.
| Category | What the auditor wants to see | What the brand produces |
|---|---|---|
| Sales journals, by period | Gross sales population by jurisdiction, the base from which everything else is reconciled | Period exports from Shopify Plus, BigCommerce, NetSuite, or QuickBooks Online, with state, taxable amount, exempt amount, and tax collected |
| Transaction-level calculation logs | Rate applied to each line, jurisdiction sourcing decision, taxability determination | A dated CSV from the tax calculation engine with date, jurisdiction code, taxable amount, rate applied, and tax computed per transaction |
| Filed returns and remittance confirmations | What was reported and what was paid for each period and registration | Copies of all filed returns with payment confirmation, or CSP filing confirmation for SST states |
| Exemption and resale certificates | Documentation supporting every transaction claimed exempt | The certificate file organized by buyer, by state, with effective and expiration dates |
| Shipping and delivery records | Destination sourcing confirmation; where the goods went, which determines the taxing jurisdiction | Carrier shipping records or 3PL exports tying each order to a ship-to address |
| Marketplace settlement reports | What each marketplace remitted by state and period, and how that maps to the credit taken on the seller's return | Settlement exports from Amazon, Walmart Marketplace, Faire, and TikTok Shop for the full audit period |
The list looks comprehensive because it is. The opening IDR is the auditor's attempt to establish the universe of records that will support or contest every later finding. What the request does not yet include, including sampling parameters, projection methodology, and contested taxability positions, comes in later IDR cycles after the field auditor has reconciled what arrived in this one against the filed returns.
For a Shopify Plus brand operating across 25 to 40 state registrations and two to four marketplace channels, the day-one production is a documentation project before it is an accounting project. The records exist. The question is whether they can be assembled in the right form, on the right schedule, without pulling the staff accountant off the monthly close for three weeks.
How to read the opening IDR for signals about audit direction
The opening IDR is more revealing than it looks. The controllers TaxCloud has watched run productive opening conferences read the request order before they touch the document inventory. What category sits at the top of the list, what is requested in unusual detail, what is specified as a native export rather than a reformatted report. The IDR is not a generic checklist. It is the auditor's bet on where the assessment is going to come from.
Three patterns recur often enough to be diagnostic.
A request that leads with exemption and resale certificates
This signals an exempt-sale reclassification focus. The auditor expects to find missing certificates, expired certificates, or certificates on the wrong form for the state, and intends to reclassify those exempt transactions as taxable. Brands with significant B2B or wholesale revenue, drop-ship arrangements, or buyer bases of 15 or more states see this pattern most often. The defensive position is a complete, current, organized certificate library with expiration tracking and buyer registration verification, ready to produce in the first cycle.
A request that leads with transaction-level calculation logs
This signals a sourcing or rate-accuracy focus. The auditor intends to test whether the calculation engine applied the correct rate at the correct jurisdiction to each transaction. Brands operating across Colorado home-rule cities, Louisiana parishes, or the stacked Cook County, RTA, Chicago, and state rate components see this pattern. The auditor usually asks for the calculation log in native format, not a summary, because they intend to recompute a sample of transactions independently and compare. TaxCloud's reporting API exports transaction-level calculation logs for any period as a dated CSV with date, jurisdiction code, taxable amount, rate applied, and tax computed: the same fields the auditor will reconcile against, in the same field order, sourced from the calculation record that produced the filed returns.
A request that leads with marketplace settlement reports
This signals a multi-channel offset focus. The auditor expects to find a gap between what the marketplace remitted, what the brand credited on its returns, and what the brand collected directly. Brands with Amazon volume above 30 percent of total revenue, Walmart Marketplace presence, TikTok Shop, or Faire wholesale see this pattern. The auditor wants settlement exports by state and period that reconcile to the credits taken, not aggregate annual totals.
Read past the lead item. Notice what the auditor specifies as a native export rather than a reformatted report; that is the record the auditor intends to test independently. Notice what date range they ask for that exceeds the audit period by a quarter or two; that is the trailing-nexus check. Notice what they ask in unusual granularity, including buyer name and address on every exempt transaction, ship-to address on every order, or rate detail on every line. That is where the sampling will land. The IDR tells the brand where the assessment risk is concentrated before fieldwork begins, which is the only time the brand can still shape the production to address it.
What's negotiable at the IDR stage: sample period, data format, system access
Scope is negotiable and brands leave that on the table. The opening IDR is a request, not a final scope. Three dimensions are negotiable before fieldwork begins, and the brand that hands over everything in the broadest form invites a broader audit than one that scopes the production tightly.
Sample period
The IDR typically asks for records covering the full proposed audit period: three years in most states, four in Texas (Tex. Tax Code §111.0041). [4] Some categories, including exemption certificates, marketplace settlement, and shipping records, do not need to be produced for the entire period in the first cycle. Negotiate a phased production: the most recent year in the opening IDR, earlier periods in subsequent cycles as the auditor's reconciliation surfaces specific questions. This compresses the first cycle without conceding records; the auditor still receives everything they are entitled to, just not all at once.
Native exports versus reformatted extracts
Auditors prefer native system exports because they want to verify the data has not been manipulated. Brands often prefer reformatted extracts because they can apply judgment to category mapping or exemption classification. The negotiation matters most for the calculation log. A native export from the tax calculation engine carries the rate determination and jurisdiction sourcing decision as the engine made them; a reformatted extract carries whatever the brand mapped the columns to. The auditor will treat the reformatted version as the brand's interpretation, not the source record. Where the underlying data is clean, produce native. Where the underlying data needs context, such as sales journals across multiple commerce platforms with inconsistent SKU taxonomies, produce both: the native export for reconciliation, the reformatted version with an explanatory cover note.
Extracts versus system access
A growing share of state audit divisions request limited read access to the brand's accounting and tax systems rather than extracts. CA CDTFA, NY DTF, and TX Comptroller field auditors increasingly accept either approach. System access lets the auditor see more and the brand produce less; the trade-off is real. Access lets the auditor pull records the brand did not anticipate producing, including aged records outside the proposed audit period. Extracts give the brand control over what the auditor sees and a documented audit trail of what was produced. At the $20M to $80M band, the right answer is almost always extracts. Brands at this scale generally do not have the system-level access controls (auditor-only read roles, query logs, period restrictions) that make limited access defensible. Document the format choice in writing at the opening conference and reference it in subsequent IDR cycles.
Each of these is a conversation at the opening conference, not a fight. The auditor knows the brand has a right to scope the production. The auditor also knows that a brand proposing a reasonable, structured production schedule has thought about what records it has, and that thinking signals controls before a single record is delivered. The brand that hands over everything in the broadest form, in whatever format the system exports, signals the opposite.
The reconciliation chain: how the production package is built
The reconciliation chain is what the auditor is actually examining. Every other category in the IDR feeds into one of four links. The opening IDR's structure tells the brand what to assemble. The production format tells the auditor whether the brand assembled it.
The chain runs from left to right:
- Sales journals establish the gross sales population by state and period.
- Transaction-level calculation logs show what tax was computed at the line level, at which jurisdiction, at which rate.
- Filed returns show what was reported to the state for each period and registration.
- Remittance confirmations show what was actually paid, through direct bank transfer or through a Certified Service Provider for SST states.
For each gap between two consecutive links, the auditor will look for an explanation. A transaction in the sales journal that is not in the calculation log is uncollected tax until explained. A calculation log entry that is not on the filed return is reported-but-not-remitted tax. A return that does not match the remittance record is a payment failure or a CSP reconciliation gap. Each gap is a finding unless the documentation closes it.
The production package that ties the chain together has three components.
An index document
A spreadsheet, by state and period, that lists every file in the production, identifies which link in the chain it covers, and notes any reconciling items. The auditor opens the index first. If it ties the production together cleanly, the rest of the production is read for what it confirms, not for what it might be hiding.
Reconciling notes for each gap
Where the sales journal and calculation log totals differ, a one-paragraph explanation: the gap is reported manual orders, a refund timing difference, or a marketplace credit applied to the period. Identifying the gap before the auditor does signals controls; explaining the gap with the supporting record reduces the chance it becomes a sampling target.
Source documentation for each link
Sales journals exported from Shopify Plus, NetSuite, or QuickBooks Online with the standard fields (date, customer, taxable amount, exempt amount, tax collected); calculation logs from the tax engine; filed returns and payment confirmations from the compliance provider; for SST states, the consolidated CSP filing statement with the brand's allocation. TaxCloud generates the calculation log and SST filing artifacts for any period through the reporting API as dated exports, with the audit-period structure already aligned to the state's measurement window. The chain ties without recutting calendar-year data to fiscal-year audit periods.
The chain is what the auditor sees. The reconciling notes are what tell the auditor whether they need to test it themselves.
Production format, delivery, and response timing
How the production is delivered shapes the auditor's read. A clean, indexed, reconciled package tells the auditor the brand has controls. A disorganized data dump invites deeper sampling because the auditor cannot trust the population. The same records, produced the two different ways, can move a final assessment by an order of magnitude.
Four format conventions hold across CA CDTFA, NY DTF, and TX Comptroller productions:
File naming
Every file encodes state, period, and document type: CA_2024-Q3_SalesJournal.xlsx, CA_2024-Q3_CalculationLog.csv, CA_2024-Q3_FiledReturn.pdf. The convention is sortable, predictable, and lets the auditor locate any specific document in seconds. The opposite, files named for who exported them with timestamps and version numbers attached, produces a production the auditor has to triage before they can examine.
Folder structure
Three levels: state, then period, then document type. One top-level folder per registered state. Within each, one subfolder per filing period. Within each period, one folder per document category. The structure mirrors the chain: anyone in the auditor's office can open the California Q3 2024 folder and see sales journal, calculation log, filed return, certificates active during the period, settlement reports, and bank reconciliation, in that order.
Delivery method
States vary. CA CDTFA accepts secure file transfer through its auditor portal or an SFTP drop. NY DTF prefers physical media or its secure messaging system. TX Comptroller accepts both. Whatever the channel, the production should be delivered in one batch per IDR cycle, with the index document at the root level, not spread across multiple emails or transfers over the course of the response window.
Written confirmation of delivery
Every production is logged: what was delivered, on what date, in what format, with which index. The log is part of the audit file the brand keeps independently of what the state retains. If the auditor later claims a document was not produced, the log is the evidence chain.
Response windows run 10 to 30 days per IDR cycle. CA CDTFA typically allows 15 to 30 days; NY DTF and TX Comptroller commonly allow 10 to 15. Extensions are routinely granted on first ask, often 10 to 15 additional days, but the request must be submitted in writing before the deadline. Silence on a deadline authorizes the auditor to proceed with whatever records are already in hand, which is the path to the least favorable projection available. Treat every IDR deadline as a hard date and the extension request as a separate work item that runs alongside the production work.
What the production-ready operating model looks like
By the time the first IDR lands, the documentation discipline the brand built before today's date is what gets graded. The brand has the notice, the opening conference is closed, the first IDR has arrived, and the question is whether the documentation discipline it built before today's date is going to hold under examination.
Three patterns hold across audits that close at the field-auditor level rather than escalating.
The records were assembled before they were requested
A pre-notice gap index, a spreadsheet listing every state, every period, every document category, with a complete-or-missing cell for each, was maintained quarterly. Missing cells were closed before the notice arrived. When the IDR landed, the production was a retrieval operation, not a research operation.
The reconciliation was tested independently before delivery
The brand reconciled sales journals to calculation logs to filed returns to remittance for each state and period in the audit window before producing anything. Gaps were identified, explained, and documented with the supporting record attached. Nothing the auditor finds in the production should surprise the brand.
The custodian was named
Each state folder had a custodian and a backup. When the auditor asked for the Texas Q2 2023 calculation log on a Tuesday, the file was retrieved by Wednesday by someone who built the folder structure or its backup. Retrieval did not become an all-hands search during an active audit.
The reader here is past wondering whether the IDR will arrive. The question is what the production layer looks like when it does. TaxCloud is built for that supply layer: transaction-level calculation logs through the reporting API for any period on demand, consolidated SST filing statements across the 23 full member states exportable by period with the CSP confirmation attached, and an exemption certificate library with expiration tracking and buyer registration verification organized by state. The controller and the staff accountant own the audit response, the legal positions, and the negotiation with the auditor. The production-ready operating model means the documentation arrives ready to support them.